keybase / keybase/keybase-issues

Twitter verification by ID, not username

Open
#1,081 10 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

A friend of mine recently [re-verified their twitter account for the third time](https://twitter.com/enbygorawr/status/516464525441110016). This is because the verification process has us sign our Twitter username, and when it changes, the signature has to be redone.

However, Twitter uses a `user_id` to enable username changes, and this ID never changes. It would be preferable, then, if the verification used that ID instead of the username, ensuring that any username change need not be followed by yet another keybase proof for essentially the same account.

As a security bonus, is there currently a mechanism that prevents someone grabbing another's usual twitter handle while they've changed temporarily (which may be done around events, like the upcoming :ghost: Halloween :jack_o_lantern:), sign that with keybase, and then be able to display, forever, a "wrong" identity on their keybase profile? Sure, manual verification of the proof tweet could alleviate consequences, but wouldn't it be better to simply sign the ID, thus proving ownership of the twitter account, no matter what handle it uses at any given time?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the existing Twitter verification flow and how proofs identify accounts; the issue names no files or tests. Done would mean verification remains tied to Twitter's stable user_id across username changes and does not allow a temporary handle change to produce a lasting wrong identity.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.